How the Exposure Index works
The Manatoko DPDP Exposure Index is a transparent, weighted scoring model that quantifies an organisation's penalty risk under India's Digital Personal Data Protection Act 2023.
Dimensions and weights
Answers are scored across five weighted dimensions, Data Volume & Sensitivity (30%), Regulatory Classification Risk (20%), Consent Architecture Maturity (20%), Children's Data Exposure (15%), and Breach Preparedness (15%), into a 0 to 100 composite and a risk band.
| Dimension | Weight | What it measures |
|---|---|---|
| Data Volume & Sensitivity | 30% | Volume of data principals, sensitivity of categories, and third-party processor chain. |
| Regulatory Classification Risk | 20% | Sector risk profile, revenue-based SDF likelihood, and regulatory classification. |
| Consent Architecture Maturity | 20% | Consent collection method, withdrawal mechanisms, and Consent Manager readiness. |
| Children's Data Exposure | 15% | Processing of minors' data, parental consent, and behavioral tracking. |
| Breach Preparedness | 15% | Breach response plans, notification capability, and DPIA status. |
Composite score = the weighted sum of the five dimension scores, rounded to a whole number from 0 to 100.
Risk bands
| Composite score | Band |
|---|---|
| 0-30 | Low |
| 31-55 | Moderate |
| 56-75 | High |
| 76-100 | Critical |
Why scoring runs server-side
The questionnaire, the interface, and your results are all visible to you. The exact per-option point values, band thresholds, and recommendation library are computed server-side, so the model is not exposed in client code. Your answers are sent only to compute your score and are never stored, logged, or shared.
Frequently asked questions
How is the exposure score calculated?
Answers are scored across five weighted dimensions, Data Volume & Sensitivity (30%), Regulatory Classification Risk (20%), Consent Architecture Maturity (20%), Children's Data Exposure (15%), and Breach Preparedness (15%), into a 0 to 100 composite and a risk band.
What do the risk bands mean?
The composite maps to four bands: Low (0 to 30), Moderate (31 to 55), High (56 to 75), and Critical (76 to 100).